By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Hermes AI Agent Automates Thai Finance Ministry Attack
An open-source artificial intelligence agent, identified as Hermes, was employed to automate post-exploitation activities during a security incident at Thailand's Ministry of Finance. The threat actor utilized Hermes in an unattended mode, specifically referred to as "YOLO" (You Only Look Once), which is designed for rapid object detection and analysis. This mode allowed the AI agent to autonomously identify and interact with systems after initial access had been gained.
The incident, which occurred on March 27, 2024, involved the unauthorized access to the Ministry's network. While the full extent of the breach and the specific data compromised are still under investigation, the use of an AI agent like Hermes signifies a growing trend in sophisticated cyberattacks. Hermes is known for its capabilities in automating tasks such as privilege escalation, lateral movement, and data exfiltration, making it a potent tool for malicious actors seeking to operate with speed and stealth.
Security researchers from Palo Alto Networks' Unit 42 first observed the use of Hermes in this attack. Their analysis indicated that the AI agent was configured to perform reconnaissance and potentially deploy further malicious payloads without direct human intervention. The "YOLO" mode, typically associated with computer vision tasks, was repurposed within the context of network exploitation, highlighting the adaptability of AI tools for cyber warfare. This development underscores the challenges faced by cybersecurity professionals in defending against AI-powered threats that can adapt and operate at machine speed.
The Ministry of Finance of Thailand has acknowledged the incident and is working with cybersecurity experts to assess the impact and strengthen its defenses. The use of Hermes in this context serves as a stark reminder of the evolving landscape of cyber threats, where AI is increasingly being weaponized. Organizations worldwide are urged to enhance their threat detection and response capabilities to counter such advanced automated attacks.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.